important · Research — Agentic systems
A public Salesforce lead could make Agentforce exfiltrate CRM records and post trusted Slack phishing messages.
Affects
Salesforce Agentforce, a cloud AI-agent platform connected to CRM records and optionally deployed into Slack workspaces.
A stored prompt submitted through Web-to-Lead can run during routine review, query other CRM tables with the employee's permissions and move values through attacker-controlled DNS without a click.
Detail and 4 sources
The affected Slack action could also post links as the agent without confirmation or initiator attribution; Salesforce patched the demonstrated chains.
Sources
ResearchSalesBleed: 0-Click Data Exfiltration in Agentforce | Zenity LabsResearchSalesforce HelpResearchSalesforceのAIエージェント経由でSlackに匿名フィッシング投稿 — 「SalesBleed」3件の欠陥をZenityが報告(修正済み) | NEXSIGHT CYBER WIRESecondarySalesBleed crosses public Salesforce input into Agentforce data access and trusted Slack actions